Privacy Policy

Effective date: July 11, 2026.

This Privacy Policy explains how OpSynx AI (“OpSynx AI,” “we,” “us”) collects, uses, discloses, and protects information in connection with the OpSynx AI platform and services (the “Service”). OpSynx AI is a business-to-business software provider. For the lead, owner, and property-owner personal information that a Customer uploads to or generates within its sub-account, the Customer is the data controller and OpSynx AI acts as the Customer’s processor; that processing is governed by the Data Processing and Data-Sharing Addendum. This Policy also describes information OpSynx AI handles as a controller for account administration and operation of the Platform.

1. Information we collect

2. How we use information

We use information to provide and operate the Service (underwriting, lead management, disposition, document generation, notifications, and support); to authenticate Users and secure the Platform; to bill and collect fees; to provide customer support; to monitor, troubleshoot, and improve the Service; and to comply with legal obligations and enforce our agreements. We do not sell personal information, and we do not use Customer Data to train general-purpose or third-party AI models.

3. Legal bases

Where applicable law requires a legal basis, we rely on performance of our contract with you, our legitimate interests in operating and securing the Service, your and your Users’ consent where required, and compliance with legal obligations. For Customer Data, we process on the documented instructions of the Customer as controller.

4. Disclosures and sub-processors

We disclose information only as needed to run the Service, to comply with law, or to protect rights and safety. Our sub-processors include: Land Portal (skip-trace and contact data), GoHighLevel (CRM and lead capture), Slack (operational notifications), DigitalOcean (cloud hosting and infrastructure), and our AI provider(s) (automated analysis and document generation). We require sub-processors to protect information consistent with this Policy, and we will give notice before adding or materially changing a sub-processor. We may also disclose information in connection with a merger, acquisition, or sale of assets, subject to this Policy.

5. Skip-trace and contact data

Skip-trace outputs are consumer contact information and are subject to privacy, telemarketing, and Do-Not-Call laws. This data is not a consumer report and may not be used for any purpose governed by the Fair Credit Reporting Act. You are solely responsible for the lawful use of this data, including honoring Do-Not-Call and consent requirements.

6. Retention and security

We retain account information for the life of your account and for a reasonable period afterward as required for legal, tax, and audit purposes. Customer Data is retained for the life of your account and is made available for export and then deleted after termination (typically within 30 days) unless law requires longer retention. We maintain administrative, technical, and physical safeguards, including per-tenant isolation, encryption in transit, role-based access controls, least-privilege credentials, and audit logging. No system is perfectly secure, and we cannot guarantee absolute security.

7. Your rights and choices

Subject to applicable law, individuals may have rights to access, correct, delete, or port their personal information, or to object to or restrict certain processing. Where OpSynx AI acts as a processor of Customer Data, we act on the Customer’s instructions and will refer requests to the Customer as controller. To exercise a right or ask a question, contact [email protected].

8. Cookies and tracking

We use strictly-necessary cookies and similar technologies for authentication, session management, and security. We do not use third-party advertising cookies or sell information for cross-context behavioral advertising.

9. International data

The Service is hosted in the United States. If you access it from outside the United States, you understand that information will be processed in the United States, and where cross-border transfer rules apply the parties will implement an appropriate transfer mechanism.

10. Children

The Service is a business product not directed to children and not intended for anyone under 18. We do not knowingly collect personal information from children.

11. Changes and contact

We may update this Policy from time to time and will post the updated effective date. Material changes will be communicated by reasonable means. Questions or requests: [email protected].